[Git][security-tracker-team/security-tracker][master] Process some NFUs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 20:59:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cb8c765c by Salvatore Bonaccorso at 2026-09-25T21:59:26+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -47,69 +47,69 @@ CVE-2026-97764 (django-allauth before 65.19.4 does not have the expected limits
NOTE: Fixed by: https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96 (65.19.4)
NOTE: Fixed by: https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83 (65.19.4)
CVE-2026-97737 (In Wakapi before 2.17.6, the user caching service allows a lookup to b ...)
- TODO: check
+ NOT-FOR-US: Wakapi
CVE-2026-97736 (tinyauth before 5.1.3 allows rule bypass by appending an allowed route ...)
- TODO: check
+ NOT-FOR-US: Tinyauth
CVE-2026-97735 (ITFlow before 26.08 allows SVG attachments in the ticket email parser ...)
- TODO: check
+ NOT-FOR-US: ITFlow
CVE-2026-97732 (IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that au ...)
- TODO: check
+ NOT-FOR-US: IRONMACE Ironshield
CVE-2026-97731 (MinIO through 7aac2a2 does not verify that every x-amz-* header presen ...)
TODO: check
CVE-2026-97730 (In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Lo ...)
- TODO: check
+ NOT-FOR-US: Netgate pfSense Plus
CVE-2026-97724 (A prototype pollution vulnerability in Software Mansion React Native W ...)
- TODO: check
+ NOT-FOR-US: Software Mansion React Native Worklets
CVE-2026-97723 (madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (X ...)
- TODO: check
+ NOT-FOR-US: madpsy ka9q_ubersdr
CVE-2026-97721 (A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. ...)
- TODO: check
+ NOT-FOR-US: Sanluan PublicCMS
CVE-2026-97650 (A vulnerability has been found in ningzichun student-management-system ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97649 (A flaw has been found in ningzichun student-management-system up to 98 ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97648 (A vulnerability was detected in ningzichun student-management-system u ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97647 (A security vulnerability has been detected in ningzichun student-manag ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97646 (A weakness has been identified in ningzichun student-management-system ...)
- TODO: check
+ NOT-FOR-US: ningzichun student-management-system
CVE-2026-97636 (Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend ...)
- TODO: check
+ NOT-FOR-US: Apache Airflow HashiCorp provider
CVE-2026-97622
REJECTED
CVE-2026-97469 (PostgreSQL Anonymizer contains a vulnerability that allows unprivilege ...)
- TODO: check
+ NOT-FOR-US: PostgreSQL Anonymizer
CVE-2026-97387
REJECTED
CVE-2026-97368 (A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. ...)
- TODO: check
+ NOT-FOR-US: chillzhuang SpringBlade
CVE-2026-97366 (A security flaw has been discovered in jhen0409 react-native-debugger ...)
- TODO: check
+ NOT-FOR-US: jhen0409 react-native-debugger
CVE-2026-97365 (A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impa ...)
- TODO: check
+ NOT-FOR-US: chonkie-inc littrs
CVE-2026-97326 (A weakness has been identified in songxinjianqwe Chat up to ac63d25297 ...)
- TODO: check
+ NOT-FOR-US: songxinjianqwe Chat
CVE-2026-97325 (A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue- ...)
- TODO: check
+ NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
CVE-2026-97324 (A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro u ...)
- TODO: check
+ NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a Grap ...)
- TODO: check
+ NOT-FOR-US: Rapid7 Bulk Export MCP
CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user opens a ...)
TODO: check
CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master login ve ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in HTTP resp ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-97060 (X-SpringBoot through 6.0 lacks object-level authorization in user mana ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-96883 (pgcollection is an open source extension to PostgreSQL. A type confusi ...)
NOT-FOR-US: Amazon
CVE-2026-96874 (Improper neutralization of input during web page generation ('cross-si ...)
- TODO: check
+ NOT-FOR-US: X-SpringBoot
CVE-2026-96812 (Improper Exposure of Resource to Wrong Sphere in the host file helper ...)
- TODO: check
+ NOT-FOR-US: Google gVisor
CVE-2026-96766 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
NOT-FOR-US: WordPress plugin
CVE-2026-96752 (The Zero Spam for WordPress plugin for WordPress is vulnerable to Stor ...)
@@ -131,7 +131,7 @@ CVE-2026-95834 (Use After Free in the drag source path of the drag and drop prot
CVE-2026-95832 (Improper Neutralization of Special Elements in Output Used by a Downst ...)
TODO: check
CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile application's AWS policy could ...)
- TODO: check
+ NOT-FOR-US: iSteamX mobile application
CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress is vulner ...)
NOT-FOR-US: WordPress plugin
CVE-2026-94445 (A malicious txtar could escape the intended execution context and forc ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/f0fb080d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list